PT-2026-64652 · Linux · Linux Kernel

CVE-2026-64431

·

Published

2026-07-25

·

Updated

2026-08-21

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description An out-of-bounds memory access occurs in the NTFS driver when ntfs icx ib sync write() calls post write mst fixup() after ntfs ib write() returns an error. The system fails to differentiate between I/O errors and validation failures from pre write mst fixup(). Because post write mst fixup() assumes the index block contents are correct and lacks boundary checks, it can be exploited via a malicious NTFS image. Specifically, an attacker can manipulate the index block.usa ofs offset to point outside the ntfs record, set index block.usa count to 0 to cause an integer underflow, or set index block.usa count to a value larger than the actual number of sectors in the ntfs record.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-64431
OPENSUSE-SU-2026:11476-1

Affected Products

Linux Kernel